AIR Security raises $50M to filter what AI agents trust

Unit 8200 veterans Yair Saban and Niv Hoffman closed two seed rounds led by Sequoia and Greenoaks within weeks of each other.

By · Published

Primary source: Ctech

Why it matters

Saban and Hoffman are betting that the software supply chain around AI agents will become a security market of its own, and investors are funding the data pipeline before platform vendors close the gap.

A finely crafted industrial-design filter mechanism on a seamless studio background, embodying AIR Security's focus on AI trust.

Yair Saban and Niv Hoffman brought AIR Security out of stealth on September 1st with $50 million across two seed rounds, giving their six-month-old cybersecurity vendor a substantial war chest to police the tools, websites and instructions entering AI agents.

The founders met in the Israeli military about a decade ago and later worked in offensive cybersecurity, enterprise infrastructure and AI security research. They founded AIR Security in February 2026 around a specific view of the agent threat: permissions tell security teams what an agent can reach, while the information entering its context can determine what it actually does.

"Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents," Saban told Ctech. His sales pitch takes the firewall concept literally. AIR Security sits inline, evaluates external content and components, and can stop an agent from loading a skill, visiting a source or invoking a tool that fails its checks.

Two seed rounds in a matter of weeks

The financing arrived in two pieces. Sequoia Capital led an initial $10 million seed round. Greenoaks led a $40 million follow-on that closed within weeks, according to TechCrunch. Swish Ventures and Netz also participated.

The angel group includes Cognition President Zach Frankel, Wiz co-founder Yinon Costica, Eon co-founder Ofir Ehrlich, former US national-security official Anne Neuberger, Clay co-founder Varun Anand, and musician and investor Omer Adam.

AIR Security plans to spend the capital on security researchers and commercial expansion in the United States and Europe. AIR Security employs about 40 people and has started hiring in the US. Ryan Knisley, who previously served as chief information security officer at Walt Disney and Costco, joined as chief strategy officer, putting an experienced enterprise buyer inside the executive team.

The unusually rapid pair of rounds reflects the race to establish control points around corporate agents before AI platforms bundle their own security layers. Saban expects model providers to add protections, but argues that enterprises will still need a vendor-neutral product spanning different models, agent frameworks and cloud environments.

The add-on supply chain is the product

AI agents can acquire new capabilities through skills, plug-ins, Model Context Protocol servers and sub-agents. Those components can introduce code, fetch changing instructions from the internet or connect an agent to internal systems. The MCP specification tells clients to treat tool annotations as untrusted unless they come from trusted servers, validate results before passing them to a model and keep humans able to deny sensitive actions.

Saban and Hoffman are betting that these precautions will become an enterprise security category of their own. AIR Security discovers approved and unauthorized agents, maps the components they use, continuously evaluates those components, and enforces policies while agents run. AIR Security is also building a marketplace where organizations can distribute pre-vetted add-ons.

Continuous evaluation is the important part of the pitch. A clean plug-in can later become dangerous if its developer account is compromised, a referenced package changes or an expired domain is acquired by somebody else. A one-time scan cannot catch a dependency that turns hostile after approval.

AIR Security has used its research operation to demonstrate that problem and generate demand for the platform. In a June 24th study, AIR Security said it scanned 142,836 live skills gathered from a public marketplace and GitHub. Its researchers classified 17,822, or 12.4%, as dependent on at least one untrusted external resource. Those skills represented about 6.7 million installations, according to AIR Security.

The methodology assigns trust scores using signals such as young domains, lightly used GitHub accounts, look-alike brands, new software packages and abandoned hosting. Those indicators describe exposure rather than confirmed malicious activity. AIR Security's figures are company-generated research and have not been independently validated.

Hoffman and researcher Or Nevo also described an experiment in which AIR Security created a skill that gained distribution while passing available security scanners. AIR Security said the skill reached more than 26,000 agents and could have accessed conversations and connected systems. The test payload collected email addresses so affected users could be notified, rather than executing a destructive action. The published account offers a concrete example of Saban's broader thesis: reputation signals and static reviews can miss instructions fetched after installation.

A crowded category, with prevention as the wedge

AIR Security competes with vendors including Noma Security, Zenity, Astrix Security and Operant AI. Their products overlap across agent discovery, identity controls, governance and runtime monitoring.

Saban is drawing AIR Security's boundary around preventive filtering and continuous re-verification of the add-on supply chain. Discovery will become common, he told TechCrunch. The harder asset to reproduce is a continuously updated system that evaluates skills, plug-ins, MCP servers and the external resources behind them.

AIR Security says its scanner currently rejects about 27% of the skills and add-ons it finds online. It also says it has more than 20 customers, roughly one-quarter of them large enterprises, with the strongest demand coming from financial-services and pharmaceutical organizations. AIR Security has not named those customers, and the traction figures remain self-reported.

The founders now have enough capital to test whether their research corpus can become durable security infrastructure. Saban said AIR Security expects significant sales during the coming year and anticipates raising additional rounds. The immediate job is to prove that enterprises will buy a separate firewall for agent context before the AI platforms make that protection a standard feature.

Reader comments

Conversation for this story loads after sign-in.